Heterogeneous redundancy apparatus for vehicle, and vehicle control method and vehicle

WO2025185357A8PCT designated stage Publication Date: 2025-10-02YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/073340
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-07
Filing Date
2025-01-20
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

In the existing technology, when vehicles use homogeneous redundant backup to ensure safe driving and parking, the cost is high and it is difficult to avoid common cause failures.

Method used

By introducing heterogeneous redundant devices in the vehicle and improving the communication topology between units, the control unit can receive instructions and control the execution unit to perform actions when the cooperative control unit fails, avoiding common cause failures and reducing hardware costs.

Benefits of technology

It improves the safety and redundancy of vehicle operation, reduces hardware equipment costs, avoids common cause failures, and ensures that the vehicle can still operate normally in the event of a failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025073340_02102025_PF_FP_ABST
    Figure CN2025073340_02102025_PF_FP_ABST
Patent Text Reader

Abstract

A heterogeneous redundancy apparatus for a vehicle. The apparatus comprises a collaborative control unit (230), one or more control units (240), and one or more execution units (250), wherein each control unit (240) correspondingly controls at least one execution unit (250); the control unit (240) is used for receiving a first control instruction and / or a second control instruction from the collaborative control unit (230), which second control instruction is sent by the collaborative control unit (230) to the control unit (240) after the collaborative control unit (230) receives the first control instruction; and the control unit (240) is used for controlling, on the basis of the first control instruction or the second control instruction, the corresponding execution unit (250) to execute a corresponding action. The present application further relates to a vehicle control method and a vehicle. In the heterogeneous redundancy apparatus for a vehicle, when a collaborative control unit has a fault, control units can still control, on the basis of a first control instruction, execution units to execute corresponding actions, such that the operation of the vehicle is ensured, thereby improving the operation safety of the vehicle, reducing the cost of hardware devices, avoiding common cause faults, and improving the redundancy capability of a vehicle system.
Need to check novelty before this filing date? Find Prior Art

Description

Vehicle heterogeneous redundant device, vehicle control method, and vehicle

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on March 7, 2024, with application number 202410266134.1 and application name “Vehicle Heterogeneous Redundancy Device, Vehicle Control Method and Vehicle”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of vehicle technology, and in particular to a vehicle heterogeneous redundant device, a vehicle control method, and a vehicle. Background Art

[0003] Autonomous driving uses artificial intelligence to assist or replace human driving, compensating for the shortcomings of human drivers. Autonomous driving requires vehicles to have enhanced features, such as braking control, vehicle stability control, and adaptive cruise control, to ensure safe driving and parking in all situations.

[0004] Currently, to ensure safe driving and parking in various situations, vehicles typically implement homogeneous redundant backups. This allows for safe driving and parking in the event of a device failure. However, using homogeneous redundant backups is costly and difficult to prevent common cause failures. Summary of the Invention

[0005] The present application provides a vehicle heterogeneous redundancy device, a vehicle control method, and a vehicle. Without adding new hardware, by improving the communication topology between each unit, the redundancy capability of the vehicle system is enhanced, the hardware equipment cost is reduced, and common cause failures are avoided.

[0006] To achieve the above objectives, this application adopts the following technical solutions:

[0007] In a first aspect, a vehicle heterogeneous redundancy device is provided, comprising a cooperative control unit, one or more control units, and one or more execution units, wherein each control unit controls at least one execution unit; the control unit is configured to receive a first control instruction and / or a second control instruction from the cooperative control unit; wherein the second control instruction is sent by the cooperative control unit to the control unit after receiving the first control instruction; and the control unit is configured to control the corresponding execution unit to perform a corresponding action according to the first control instruction or the second control instruction.

[0008] The solution provided in the first aspect above, without adding new hardware, improves the communication topology between the units so that the control unit can receive the first control instruction and / or the second control instruction of the cooperative control unit. Therefore, when the cooperative control unit fails, the control unit can still control the execution unit to perform corresponding actions according to the first control instruction to ensure the operation of the vehicle, improve the safety of vehicle operation, reduce hardware equipment costs, avoid common cause failures, and enhance the redundancy capability of the vehicle system.

[0009] As a possible implementation, the vehicle heterogeneous redundancy device further includes an autonomous driving control unit. The autonomous driving control unit is configured to send a first control instruction to the auxiliary control unit upon receiving status information from the auxiliary control unit, and to send the first control instruction to the control unit upon not receiving status information from the auxiliary control unit. In this way, the autonomous driving control unit detects the status of the auxiliary control unit and, if a failure occurs in the auxiliary control unit, sends the first control instruction to the control unit. This allows the control unit to continue to execute the corresponding action according to the first control instruction, thereby ensuring vehicle operation and improving vehicle safety.

[0010] As one possible implementation, the status information is fed back by the auxiliary control unit upon receiving a first status query command from the automated driving control unit. Thus, the automated driving control unit detects the status of the auxiliary control unit and, if a failure occurs in the auxiliary control unit, sends the first control command to the control unit. This allows the control unit to continue executing the corresponding actions according to the first control command, thereby ensuring vehicle operation and improving vehicle safety.

[0011] As a possible implementation, the autonomous driving control unit is further configured to send a first control instruction to the control unit when a collision risk is identified. Directly sending the first control instruction to the control unit upon collision risk identification can reduce vehicle control latency and improve vehicle operation safety.

[0012] As one possible implementation, the control unit is configured to, upon receiving status information from the co-control unit, control the corresponding execution unit to perform a corresponding action according to the second control instruction, and, upon not receiving status information from the co-control unit, control the corresponding execution unit to perform a corresponding action according to the received first control instruction. In this way, by identifying the status of the co-control unit, the control unit can determine the instruction and control the execution unit based on the instruction.

[0013] As a possible implementation, the status information is fed back by the co-control unit after receiving the second status query instruction sent by the control unit. In this way, by identifying the status of the co-control unit, the control unit can easily determine the instruction and control the execution unit based on the instruction.

[0014] As one possible implementation, the cooperative control unit is configured to determine the vehicle's state change target based on the first control instruction and, based on the state change target, send corresponding second control instructions to each control unit. This coordinated implementation of multiple control units allows for better vehicle posture control, smoother vehicle operation, and greater user comfort.

[0015] As one possible implementation, the cooperative control unit is configured to obtain vehicle status data; adjust the state change target based on the vehicle status data to obtain an adjusted state change target; and send corresponding second control instructions to each control unit based on the adjusted state change target. In this way, by adjusting and optimizing the vehicle's state change target based on the vehicle status data, the vehicle's operation can be controlled based on the optimized state change target, thereby improving the smoothness and safety of vehicle operation.

[0016] As a possible implementation, the cooperative control unit obtains the usage status of each control unit and the usage status of the execution unit corresponding to each control unit; and based on the state change target, the usage status of each control unit, and the usage status of the execution unit corresponding to each control unit, sends a corresponding second control instruction to each control unit. In this way, by obtaining the usage status of the control unit and the execution unit, the second control instruction for the control unit is obtained based on the usage status of the control unit and the execution unit. Therefore, if a control unit and / or the execution unit fails, the relevant capabilities can be supplemented by other control units, making the vehicle controllable and improving vehicle safety.

[0017] As a possible implementation, the vehicle heterogeneous redundancy device further includes a mode switching unit configured to switch the vehicle's driving mode. By switching the vehicle's driving mode through the mode switching unit, the user's driving experience and safety can be improved.

[0018] As one possible implementation, the vehicle's driving modes include a manual driving mode, a first autonomous driving mode, a second autonomous driving mode, and a risk emergency mode. The mode switching unit is configured to: when the vehicle is in the first autonomous driving mode, if an anomaly occurs in the first autonomous driving mode and the manual driving mode is not activated properly, switch the first autonomous driving mode to the second autonomous driving mode; or, when the vehicle is in the manual driving mode, if an anomaly occurs in the manual driving mode, switch the manual driving mode to the second autonomous driving mode; or, if an anomaly occurs in the manual driving mode, the first autonomous driving mode, or the second autonomous driving mode, switch to the risk emergency mode. Thus, by setting multiple driving modes and switching them through the mode switching unit, it is possible to switch to manual driving if an autonomous driving failure occurs. If a manual driving failure occurs, autonomous driving can supplement risk control, such as in the second autonomous driving mode, thereby improving vehicle operation safety.

[0019] As one possible implementation, the control unit is configured to control the corresponding execution unit to execute corresponding actions according to a preset strategy when the vehicle's driving mode is in risk emergency mode. By configuring the control unit with this strategy, the vehicle can remain controllable, maintaining maximum stability and applying the brakes when both autonomous and manual driving experience anomalies, thereby reducing the risk of accidents and improving vehicle safety.

[0020] In a second aspect, a vehicle control method is provided, which is applied to a control unit in a vehicle heterogeneous redundant device described in any possible implementation of the first aspect. The method includes: the control unit receiving a first control instruction and / or a second control instruction from a co-control unit; wherein the second control instruction is sent by the co-control unit to the control unit after receiving the first control instruction; and the control unit controlling a corresponding execution unit to perform a corresponding action according to the first control instruction or the second control instruction.

[0021] The solution provided in the second aspect above, without adding new hardware, improves the communication topology between the units so that the control unit can receive the first control instruction and / or the second control instruction of the cooperative control unit. Therefore, when a failure occurs in the cooperative control unit, the control unit can still control the execution unit to perform corresponding actions according to the first control instruction to ensure the operation of the vehicle, improve the safety of vehicle operation, reduce hardware equipment costs, avoid common cause failures, and enhance the redundancy capability of the vehicle system.

[0022] As a possible implementation, the control unit controls the corresponding execution unit to perform a corresponding action according to the first control instruction or the second control instruction, including: when the control unit receives status information from the cooperative control unit, the control unit controls the corresponding execution unit to perform the corresponding action according to the second control instruction; when the control unit does not receive status information from the cooperative control unit, the control unit controls the corresponding execution unit to perform the corresponding action according to the received first control instruction. In this way, by identifying the status of the cooperative control unit, it is easier for the control unit to determine the instruction and control the execution unit based on the instruction.

[0023] As a possible implementation, the status information is fed back by the co-control unit after receiving the second status query instruction sent by the control unit. In this way, by identifying the status of the co-control unit, the control unit can easily determine the instruction and control the execution unit based on the instruction.

[0024] As one possible implementation, the method further includes: when the vehicle's driving mode is the risk emergency mode, the control unit controls the corresponding execution unit to execute corresponding actions according to a preset strategy. By configuring the control unit with this strategy, the vehicle can remain controllable, maintain maximum stability, and apply brakes when both automatic and manual driving experience anomalies, thereby reducing the occurrence of vehicle accidents and improving vehicle safety.

[0025] In a third aspect, a vehicle control method is provided, which is applied to a cooperative control unit in a vehicle heterogeneous redundant device described in any possible implementation manner of the first aspect, the method comprising: the cooperative control unit receiving a first control instruction; the cooperative control unit obtaining a second control instruction for each control unit based on the first control instruction; and the cooperative control unit sending the second control instruction to each control unit.

[0026] The solution provided in the third aspect above realizes the first control instruction by controlling the coordinated cooperation of multiple control units by the cooperative control unit, which can better control the vehicle posture, make the vehicle run more smoothly, and make the user feel more comfortable.

[0027] As one possible implementation, the cooperative control unit, based on the first control instruction, obtains a second control instruction for each control unit. This includes: obtaining a vehicle state change target based on the first control instruction; and sending a corresponding second control instruction to each control unit based on the state change target. This coordinated implementation of multiple control units achieves the state change target, enabling better vehicle posture control, smoother vehicle operation, and greater user comfort.

[0028] As a possible implementation, sending corresponding second control instructions to each control unit based on a state change target includes: obtaining vehicle state data; adjusting the state change target based on the vehicle state data to obtain an adjusted state change target; and sending corresponding second control instructions to each control unit based on the adjusted state change target. In this way, by adjusting and optimizing the vehicle's state change target based on the vehicle state data, the vehicle's operation can be controlled based on the optimized state change target, thereby improving the smoothness and safety of vehicle operation.

[0029] As a possible implementation, sending corresponding second control instructions to each control unit based on a state change target includes: obtaining the usage status of each control unit and the usage status of the execution unit corresponding to each control unit; and sending corresponding second control instructions to each control unit based on the state change target, the usage status of each control unit, and the usage status of the execution unit corresponding to each control unit. In this way, by obtaining the usage status of the control unit and the execution unit, the second control instruction of the control unit is obtained based on the usage status of the control unit and the execution unit. Therefore, when a control unit and / or the execution unit fails, the relevant capabilities can be supplemented by other control units, making the vehicle controllable and improving vehicle safety.

[0030] In a fourth aspect, a controller is provided, comprising a first instruction receiving module and a control module; the first instruction receiving module is used to receive a first control instruction and / or a second control instruction from a co-control unit; wherein the second control instruction is sent by the co-control unit to the control unit after receiving the first control instruction; the control module is used to control the corresponding execution unit to perform corresponding actions according to the first control instruction or the second control instruction.

[0031] The solution provided in the fourth aspect above, without adding new hardware, improves the communication topology between the units, so that the controller can receive the first control instruction and / or the second control instruction of the cooperative control unit, so that when the cooperative control unit fails, the controller can still control the execution unit to perform corresponding actions according to the first control instruction to ensure the operation of the vehicle, improve the safety of vehicle operation, reduce hardware equipment costs, avoid common cause failures, and enhance the redundancy capability of the vehicle system.

[0032] As a possible implementation, the control module is configured to control the corresponding execution unit to perform a corresponding action according to the second control instruction upon receiving status information from the cooperative control unit; and to control the corresponding execution unit to perform a corresponding action according to the received first control instruction upon not receiving status information from the cooperative control unit. In this way, by identifying the status of the cooperative control unit, the controller can determine the instruction and control the execution unit based on the instruction.

[0033] As a possible implementation, the state information is fed back by the cooperative control unit after receiving the second state query instruction sent by the control module. In this way, by identifying the state of the cooperative control unit, the controller can determine the instruction and control the execution unit based on the instruction.

[0034] As one possible implementation, when the vehicle's driving mode is in risk emergency mode, the control module controls the corresponding execution unit to execute the corresponding action according to the preset strategy. This configuration strategy ensures that even when both autonomous and manual driving experience anomalies, the vehicle remains controllable, maintaining maximum stability and applying the brakes, thereby reducing the risk of accidents and improving vehicle safety.

[0035] In the fifth aspect, a controller is provided, including a second instruction receiving module, a processing module and an instruction sending module, wherein the second instruction receiving module is used to receive the first control instruction; the processing module is used to obtain the second control instruction of each control unit based on the first control instruction; and the instruction sending module is used to send the second control instruction to each control unit.

[0036] The solution provided in the fifth aspect above realizes the first control instruction by controlling the coordinated cooperation of multiple control units, which can better control the vehicle posture, make the vehicle run more smoothly, and provide users with a more comfortable experience.

[0037] As one possible implementation, the processing module is configured to: derive a vehicle state change target based on the first control instruction; and, based on the state change target, send corresponding second control instructions to each control unit. This allows multiple control units to coordinate and achieve the state change target, resulting in better vehicle posture control, smoother vehicle operation, and a more comfortable user experience.

[0038] As one possible implementation, the processing module is configured to: obtain vehicle status data; adjust the state change target based on the vehicle status data to obtain an adjusted state change target; and send corresponding second control instructions to each control unit based on the adjusted state change target. In this way, by adjusting and optimizing the vehicle's state change target based on the vehicle status data, the vehicle's operation can be controlled based on the optimized state change target, thereby improving the smoothness and safety of vehicle operation.

[0039] As one possible implementation, the processing module is configured to: obtain the usage status of each control unit and the usage status of the execution unit corresponding to each control unit; and send a corresponding second control instruction to each control unit based on the state change target, the usage status of each control unit, and the usage status of the execution unit corresponding to each control unit. In this way, by obtaining the usage status of the control unit and the execution unit, the second control instruction for the control unit is obtained based on the usage status of the control unit and the execution unit. Thus, if a control unit and / or the execution unit fails, the relevant capabilities can be supplemented by other control units, making the vehicle controllable and improving vehicle safety.

[0040] In a sixth aspect, a controller is provided for executing the method described in any possible implementation manner of the second aspect.

[0041] In a seventh aspect, a controller is provided for executing the method described in any possible implementation manner of the third aspect.

[0042] In an eighth aspect, a vehicle is provided, comprising the vehicle heterogeneous redundancy device described in any possible implementation manner in the first aspect.

[0043] In the ninth aspect, a vehicle is provided, comprising one or more of the controller described in the sixth aspect and the controller described in the seventh aspect.

[0044] In the tenth aspect, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processing circuit, the method described in any possible embodiment of the second aspect is implemented, or the method described in any possible embodiment of the third aspect is implemented.

[0045] In the eleventh aspect, a chip system is provided, which includes a processing circuit and a storage medium, in which computer program instructions are stored; when the computer program instructions are executed by the processing circuit, the method described in any possible embodiment of the second aspect is implemented, or the method described in any possible embodiment of the third aspect is implemented.

[0046] In the twelfth aspect, a computer program product comprising instructions is provided, which, when the computer program product is run on a computer, enables the computer to execute a method as described in any possible implementation of the second aspect, or to implement a method as described in any possible implementation of the third aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] FIG1 is a schematic diagram of a redundant architecture of a vehicle in conventional technology;

[0048] FIG2 is a schematic structural diagram of a vehicle provided in an embodiment of the present application;

[0049] FIG3 is a schematic diagram of a structure of a vehicle heterogeneous redundancy device according to an embodiment of the present application;

[0050] FIG4 is a schematic diagram of switching driving modes provided in an embodiment of the present application;

[0051] FIG5 is one of the interactive schematic diagrams of the vehicle control method provided in an embodiment of the present application;

[0052] FIG6 is a schematic diagram of one of the application scenarios of the cooperative control unit provided in an embodiment of the present application;

[0053] FIG7 is a second schematic diagram of an application scenario of the cooperative control unit provided in an embodiment of the present application;

[0054] FIG8 is a third schematic diagram of an application scenario of the cooperative control unit provided in an embodiment of the present application;

[0055] FIG9 is a fourth schematic diagram of an application scenario of the cooperative control unit provided in an embodiment of the present application;

[0056] FIG10 is a second structural diagram of a vehicle heterogeneous redundancy device provided in an embodiment of the present application;

[0057] FIG11 is a fifth schematic diagram of an application scenario of the cooperative control unit provided in an embodiment of the present application;

[0058] FIG12 is a sixth schematic diagram of an application scenario of the cooperative control unit provided in an embodiment of the present application;

[0059] FIG13 is a schematic diagram of an application scenario of a backup cooperative control unit provided in an embodiment of the present application;

[0060] FIG14 is a third structural diagram of a vehicle heterogeneous redundancy device provided in an embodiment of the present application;

[0061] FIG15 is a second interactive diagram of the vehicle control method provided in an embodiment of the present application;

[0062] FIG16 is a schematic diagram of a scenario in a first autonomous driving mode provided by an embodiment of the present application;

[0063] FIG17 is a schematic diagram of a scenario in a second autonomous driving mode provided by an embodiment of the present application;

[0064] FIG18 is a schematic diagram of a scenario in manual driving mode provided by an embodiment of the present application;

[0065] FIG19 is a schematic diagram of one of the application scenarios of the control unit provided in an embodiment of the present application;

[0066] FIG20 is a second schematic diagram of an application scenario of a control unit provided in an embodiment of the present application;

[0067] FIG21 is a third schematic diagram of an application scenario of a control unit provided in an embodiment of the present application;

[0068] FIG22 is a fourth schematic diagram of an application scenario of a control unit provided in an embodiment of the present application;

[0069] FIG23 is a schematic structural diagram of a controller 300 provided in an embodiment of the present application;

[0070] FIG24 is a schematic diagram of the structure of a controller 400 provided in an embodiment of the present application;

[0071] FIG25 is a schematic structural diagram of an electronic device 500 provided in an embodiment of the present application. DETAILED DESCRIPTION

[0072] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0073] The terms "including," "having," and any variations thereof mentioned in the description of the embodiments of the present application are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or units is not limited to the listed steps or units, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to the process, method, product, or apparatus.

[0074] In the following, the terms "first," "second," etc. are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the quantity of the technical features indicated. Therefore, a feature specified as "first," "second," etc. may explicitly or implicitly include one or more of the features.

[0075] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0076] In the description of the embodiments of this application, unless otherwise specified, "plurality" means two or more. "And / or" in this document is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, or B exists alone.

[0077] As described in the background, autonomous driving uses artificial intelligence to assist or replace human driving, compensating for the shortcomings of human drivers. Autonomous driving requires vehicles to possess enhanced features, such as braking control, vehicle stability control, and adaptive cruise control, to ensure safe driving and parking in all situations. This places high demands on vehicle redundancy.

[0078] At present, in order to ensure that vehicles can drive and park safely under various circumstances, vehicles usually perform homogeneous redundant backup of equipment, so that when the equipment fails, the backup equipment can respond in time to ensure the safe driving and parking of the vehicle. Taking the controller and actuator as an example, as shown in Figure 1, a first controller and a second controller are set on the vehicle, where the first controller is the main controller and the second controller is the backup controller. When the first controller fails, the vehicle can be controlled by the second controller. The steering control system on the vehicle is also equipped with a first steering actuator and a second steering actuator. When the first steering actuator fails, the vehicle can be steered based on the second steering actuator. The braking control system on the vehicle is also equipped with a first brake actuator and a second brake actuator. When the first brake actuator fails, the vehicle can be braked based on the second brake actuator.

[0079] The redundant architecture shown in Figure 1 has a relatively simple hierarchy. Furthermore, due to the use of homogeneous redundant backup, identical devices, and identical internal processing logic, it is difficult to avoid common cause failures, and this also increases hardware equipment costs.

[0080] Based on the above research, an embodiment of the present application provides a vehicle heterogeneous redundancy device. Without adding hardware components, by improving the communication topology between each unit, when a failure occurs in the cooperative control unit, the control unit can still receive the first control instruction and control the execution unit according to the first control instruction to ensure the operation of the vehicle, thereby improving the safety of vehicle operation, reducing hardware equipment costs, avoiding common cause failures, and improving the redundancy capability of the vehicle system.

[0081] The vehicle heterogeneous redundancy device provided in the embodiments of the present application is deployed in a vehicle for controlling the operation of the vehicle. For example, the vehicle described in the embodiments of the present application can be a means of transportation (such as a car, bus, subway, high-speed rail, motorcycle, flying car, train, etc.), an industrial vehicle (such as a forklift, trailer, tractor, etc.), an engineering vehicle (such as an excavator, bulldozer, crane, etc.), agricultural equipment (such as a lawn mower, harvester, etc.), amusement equipment, a toy vehicle, a boat, an air cushion vehicle, a submarine, an airplane, a helicopter, etc. The embodiments of the present application do not limit the specific type, form, and function of the vehicle.

[0082] For ease of understanding, the following first introduces the structure of the vehicle. As shown in FIG2 , the vehicle 100 provided in the embodiment of the present application includes various subsystems, such as a travel system 110 , a control system 120 , and a communication system 130 .

[0083] Among other things, the travel system 110 may include components that provide powered movement for the vehicle 100. For example, the travel system 110 may include an engine, a power source, a transmission, and wheels / tires.

[0084] The engine may be an internal combustion engine, an electric motor, an air compression engine, or a combination of other types of engines, such as a hybrid engine consisting of a gasoline engine and an electric motor, or a hybrid engine consisting of an internal combustion engine and an air compression engine. The engine converts an energy source into mechanical energy. Examples of energy sources include gasoline, diesel, other petroleum-based fuels, propane, other compressed gas-based fuels, ethanol, solar panels, batteries, and other sources of electricity. The energy source may also provide energy to other systems of the vehicle 100. A transmission may transmit the mechanical power from the engine to the wheels. The transmission may include a gearbox, a differential, and a drive shaft.

[0085] In the embodiment of the present application, the control system 120 is used to control the vehicle 100 and its components to perform corresponding operations. As an example, the control system 120 may include an on-board domain controller.

[0086] In some examples, the domain controller can be divided into several domains (also called "functional domains") according to the functions of various parts of the car, such as the intelligent driving domain, cockpit domain, chassis domain, power domain, body domain, etc. Based on this, the on-board domain controller may include but is not limited to any one or more of the following: intelligent driving domain controller, cockpit domain controller, chassis domain controller, power domain controller, body domain controller. Among them, the intelligent driving domain controller is mainly used to provide autonomous driving perception, decision-making and other services, such as image information reception, image information processing and judgment, data processing and calculation, navigation and route planning, and rapid judgment and decision-making for real-time situations. The intelligent driving domain controller needs to process algorithms at the three levels of perception, decision-making, and control, and has the highest requirements for the domain controller's software and hardware. The cockpit domain controller is mainly used to control various electronic information system functions in the vehicle's intelligent cockpit, such as the central control system, in-vehicle infotainment system, head-up display, seat system, instrument system, rearview mirror system, driving behavior monitoring system, navigation system, etc. The chassis domain controller is primarily used to control the vehicle's driving behavior and posture. Its functions include, but are not limited to, brake system management, transmission system management, driving system management, steering system management, vehicle speed sensor management, body posture sensor management, air suspension system management, and airbag system management. The power domain controller is primarily used to control the vehicle's powertrain, optimize the vehicle's power performance, and ensure vehicle power safety. These functions include engine management, transmission management, battery management, power distribution management, emissions management, speed limit management, and fuel and power management. The body domain controller is primarily used to control various vehicle body functions, including, but not limited to, control of headlights, taillights, interior lights, door locks, windows, sunroof, wipers, electric trunk, smart key, air conditioning, antenna, and gateway communications.

[0087] It is understandable that the control system 120 may further include more or fewer components, and the above description of the control system 120 is not intended to limit the control system 120 .

[0088] In the embodiment of the present application, the communication system 130 may be used for signal interaction between various systems. For example, the control system 120 may interact with other systems via the communication system 130 .

[0089] It is understood that vehicle 100 may include more or fewer subsystems, and each subsystem may include multiple components. For example, vehicle 100 may also include a computer system, a sensor system, etc., which are not described in detail in the embodiments of this application. Figure 1 should not be construed as limiting the embodiments of this application. It is understood that each subsystem and component of vehicle 100 may be interconnected via wired or wireless connections.

[0090] In an embodiment of the present application, the vehicle heterogeneous redundancy device may be an intelligent control system composed of multiple mutually cooperating modules on the vehicle, and the multiple mutually cooperating modules may be located in different devices or be composed of different devices.

[0091] In the embodiments of the present application, the vehicle heterogeneous redundancy device can be used in driving scenarios corresponding to various driving modes of the vehicle to enhance the system redundancy capability of the vehicle in various driving scenarios. The driving scenarios corresponding to various driving modes refer to the driving scenarios when the vehicle uses each driving mode.

[0092] To facilitate users in using the vehicle, the vehicle provided in the embodiment of the present application is configured with multiple driving modes, such as automatic driving mode, manual driving mode and risk emergency mode.

[0093] Automatic driving mode refers to a mode in which the vehicle controls its own operations without human intervention. For example, when a vehicle is in automatic driving mode, the vehicle can automatically determine the current state of the vehicle and its surroundings without human intervention, and plan and control operations such as driving, braking, and steering based on this information. Manual driving mode refers to a mode in which humans are manually operated. For example, when a vehicle is in manual driving mode, the vehicle can control its operations by receiving operational information from humans.

[0094] Risk emergency mode refers to a driving mode that ensures the vehicle remains controllable when manual driving mode and automatic driving mode cannot operate normally.

[0095] In order to enhance the autonomous driving capability of the vehicle and improve the safety of the vehicle during operation, in an embodiment of the present application, the autonomous driving mode includes a first autonomous driving mode and a second autonomous driving mode. Among them, the first autonomous driving mode refers to the normal operation mode of autonomous driving, and the second autonomous driving mode refers to the minimum risk maneuver (MRM) mode of autonomous driving. When the vehicle adopts the first autonomous driving mode, the vehicle can normally perceive the current state of the vehicle state and the surrounding environment of the vehicle, and plan the driving intention based on information such as the vehicle state and the environmental state, and control the operation based on the driving intention. When the vehicle adopts the second autonomous driving mode, the vehicle enters the minimum risk control state in autonomous driving to help users effectively control pull-over parking or parking in the lane.

[0096] In order to improve the safety of vehicle operation, as shown in FIG3 , the vehicle heterogeneous redundancy device 200 provided in an embodiment of the present application includes a mode switching unit 210 and an automatic driving control unit 220 .

[0097] The mode switching unit 210 is used to switch the vehicle's driving mode. Exemplarily, when the vehicle is in the first automatic driving mode, if the mode switching unit 210 detects an abnormality in the first automatic driving mode and the manual driving mode is not activated normally, the first automatic driving mode is switched to the second automatic driving mode. Exemplarily, when the vehicle is in the manual driving mode, if the mode switching unit 210 detects an abnormality in the manual driving mode, the manual driving mode is switched to the second automatic driving mode. Exemplarily, if the mode switching unit 210 detects an abnormality in all of the manual driving mode, the first automatic driving mode, and the second automatic driving mode, the vehicle's driving mode is switched to the risk emergency mode.

[0098] The autonomous driving control unit 220 is configured to receive information such as the vehicle state and the state of the vehicle's surrounding environment in both the first and second autonomous driving modes, and output driving intent based on this information to control vehicle operation. The autonomous driving control unit can be a mobile data center (MDC), a vehicle control unit (VCU), or another separate controller.

[0099] In some examples, the autonomous driving control unit 220 includes multiple sub-control units, each of which can be used to control different autonomous driving modes and output driving intent in each mode. For example, a first sub-control unit among the multiple sub-control units is used to control a first autonomous driving mode and output driving intent in the first autonomous driving mode, while a second sub-control unit among the multiple sub-control units is used to control a second autonomous driving mode and output driving intent in the second autonomous driving mode. The different sub-control units can be different controllers or deployed in different controllers.

[0100] As shown in Figure 4, when the vehicle is in the first automatic driving mode, when the mode switching unit 210 detects that a user has taken over the vehicle, it will switch the first automatic driving mode to the manual driving mode. When the vehicle is in the manual driving mode, when the mode switching unit 210 detects that the user has turned on the automatic driving, it will switch the manual driving mode to the first automatic driving mode.

[0101] When the vehicle is in the first autonomous driving mode, if the mode switching unit 210 detects an anomaly in the first autonomous driving mode, such as an anomaly in the perception or planning functions, the autonomous driving control unit 220 is unable to properly output the first control command in the first autonomous driving mode, and no user has taken over the vehicle, i.e., the manual driving mode has not been properly activated, the mode switching unit 210 will switch the first autonomous driving mode to the second autonomous driving mode to minimize the risk of autonomous driving. After switching to the second autonomous driving mode, the autonomous driving control unit 220 can control the vehicle to pull over or park in its lane to improve vehicle safety. After controlling the vehicle to pull over or park in its lane, i.e., after the second autonomous driving mode ends and the vehicle restarts, the mode switching unit 210 will switch the vehicle's driving mode back to the first autonomous driving mode.

[0102] When the vehicle is in manual driving mode, if the mode switching unit 210 detects an abnormality in the manual driving mode, such as a malfunction in the steering wheel, brake pedal, or accelerator pedal input, resulting in the vehicle being unable to receive the user's driving intent, the mode switching unit 210 will switch the manual driving mode to the second, automated driving mode, to minimize risk. After switching to the second, automated driving control unit 220 can control the vehicle to pull over or park in its lane, thereby improving vehicle safety.

[0103] In some examples, after an anomaly occurs in the first autonomous driving mode and the mode switching unit 210 switches the driving mode to the second autonomous driving mode, if it detects that the second autonomous driving mode is also anomaly, such as being unable to output the driving intention to pull over and the user has not effectively taken over the vehicle (such as input failure of the steering wheel, brake pedal, accelerator pedal, etc.), the vehicle's driving mode will be switched to the risk emergency mode. That is, if an anomaly occurs in the first autonomous driving mode, the second autonomous driving mode, and the manual driving mode, the vehicle's driving mode will be switched to the risk emergency mode. After switching to the risk emergency mode, the vehicle enters a preset static configuration scenario and controls vehicle operation according to the set strategy.

[0104] The embodiments of the present application provide multiple driving modes and switch between them through a mode switching unit. This allows for switching to manual driving if an autonomous driving failure occurs. In the event of a manual driving failure, autonomous driving can supplement risk control, such as in the second autonomous driving mode, to improve vehicle operation safety.

[0105] To further enhance the vehicle's controllability in various driving modes and improve the safety and comfort of vehicle operation, as shown in Figure 3, the vehicle heterogeneous redundancy device 200 also includes a co-control unit 230, one or more control units 240, and one or more execution units 250. The one or more control units 240 are connected to the co-control unit 230, and each control unit 240 corresponds to at least one execution unit 250, and each control unit 240 is connected to the corresponding execution unit 250.

[0106] The embodiment of the present application does not limit the connection method between the control unit 240 and the cooperative control unit 230, and the connection method between the control unit 240 and the execution unit 210. For example, it can be a communication connection or an electrical connection, which is specifically set according to actual needs.

[0107] In an embodiment of the present application, the cooperative control unit 230 can enable one or more control units 240 to cooperatively control the corresponding execution units based on the driving intention of the vehicle to improve the comfort and stability of the vehicle operation.

[0108] As an example, in software implementation, the cooperative control unit 230 can be a piece of code or a binary file configured in one or more controllers. When the cooperative control unit 230 is executed, the instructions corresponding to the code or binary file will be executed by the corresponding controller. In some feasible situations, the cooperative control unit 230 can be configured in the vehicle controller. In some feasible situations, the cooperative control unit 230 can also be a separate controller or composed of multiple controllers. The embodiment of the present application does not limit the type of the cooperative control unit 230 and is set according to actual needs.

[0109] In the embodiment of the present application, the control unit 240 refers to a unit that outputs instructions to the execution unit.

[0110] As an example, the control unit 240 included in the vehicle heterogeneous redundant device 200 may be one or more of an X-direction control unit, a Y-direction control unit, and a Z-direction control unit.

[0111] The X-direction refers to the vehicle's direction of travel, the Z-direction refers to the vehicle's vertical direction, and the Y-direction refers to the direction perpendicular to both the direction of travel and the vertical direction. An X-direction control unit controls the vehicle's state in the X-direction, such as a drive control unit, a brake control unit, or a parking control unit. A Y-direction control unit controls the vehicle's state in the Y-direction, such as a front-wheel steering control unit or a rear-wheel steering control unit. A Z-direction control unit controls the vehicle's state in the Z-direction, such as a suspension control unit.

[0112] As an example, each control unit 240 is a separate controller or is composed of multiple controllers. In some examples, in software implementation, the control unit 240 can also be a piece of code or a binary file configured in one or more controllers. When the control unit 240 is executed, the instructions corresponding to the code or binary file will be executed by the corresponding controller. The embodiment of the present application does not limit the type of control unit 240, and it is set according to actual needs.

[0113] In some examples, the autonomous driving control unit 220, the cooperative control unit 230, and the control unit 240 may be controllers in an on-board domain controller, or controllers deployed in the above-mentioned on-board domain controller.

[0114] In the embodiment of the present application, the execution unit 250 refers to a mechanism that executes the instructions output by the control unit, for example, a motor drive mechanism, a brake mechanism, a parking mechanism, a steering mechanism, a suspension mechanism, etc.

[0115] Different execution units 250 are controlled by corresponding control units and perform corresponding actions according to the instructions of the corresponding control units 240 to achieve control over the operation of the vehicle. For example, the motor drive mechanism can receive a drive instruction from the drive control unit and control the vehicle to drive according to the drive instruction. For another example, the brake mechanism can receive a brake instruction from the brake control unit and control the vehicle to brake according to the brake instruction. For another example, the parking mechanism can receive a parking instruction from the parking control unit and control the vehicle to park according to the parking instruction. For another example, the steering mechanism can receive a steering instruction from the steering control unit and control the vehicle to steer according to the steering instruction. For another example, the suspension mechanism can receive a height adjustment instruction from the suspension control unit and adjust the height of the vehicle according to the height adjustment instruction.

[0116] Based on the vehicle heterogeneous redundant device shown in FIG3 , an embodiment of the present application provides a vehicle control method, which can be applied to the cooperative control unit in FIG3 . Please refer to FIG5 , which is one of the interactive schematic diagrams of the vehicle control method provided in the embodiment of the present application. For ease of understanding, FIG5 only illustrates one control unit and one corresponding execution unit. It can be understood that other control units and execution units are also based on the same process and are not shown in FIG5 . As shown in FIG5 , in the embodiment of the present application, the cooperative control unit can execute the process from step S201 to step S202.

[0117] S201: Receive a first control instruction.

[0118] In an embodiment of the present application, the first control instruction is used to represent the vehicle driving intention, such as steering, braking, etc.

[0119] In the embodiments of the present application, the source of the first control command varies in different driving modes. For example, when the vehicle driving mode is manual, the first control command may be issued by a human-machine interface device. The human-machine interface device may include, but is not limited to, an accelerator pedal, a brake pedal, a steering wheel, or a vehicle computer. The embodiments of the present application do not limit the type of human-machine interface device; it may be configured based on actual needs.

[0120] In an embodiment of the present application, when the vehicle driving mode is an automatic driving mode (such as a first automatic driving mode or a second automatic driving mode), the first control instruction may be issued by an automatic driving control unit.

[0121] It is understood that the above is merely an example of the source of the first control instruction in the embodiment of the present application and is not intended to be a specific limitation. In some examples, the first control instruction may also come from a terminal device (such as a mobile phone), and the user inputs the first control instruction to the vehicle through the terminal device. The specific setting depends on actual needs.

[0122] S202: Obtain a second control instruction for each control unit according to the first control instruction, and send the second control instruction to each control unit.

[0123] In an embodiment of the present application, the second control instruction is used to represent the control information theoretically output by each control unit to the corresponding execution unit after the cooperative control unit receives the first control instruction and analyzes the driving intention represented by the first control instruction.

[0124] For example, after receiving the first control instruction, the cooperative control unit parses the first control instruction to obtain the vehicle's state change target, and sends a second control instruction to each control unit based on the vehicle's state change target, so that each control unit can control the corresponding execution unit to perform corresponding actions according to the second control instruction.

[0125] As an example, in an autonomous driving mode (such as the first autonomous driving mode and the second autonomous driving mode), the autonomous driving control unit may interpret the driving intention as a state change target and send a first control instruction to the cooperative control unit based on the state change target, i.e., the first control instruction includes the state change target. After receiving the first control instruction, the cooperative control unit may obtain the state change target.

[0126] As an example, in manual driving mode, after receiving the user's driving intention, the human-machine interaction device sends a first control instruction to the cooperative control unit. The first control instruction includes the user's driving intention. After receiving the first control instruction, the cooperative control unit analyzes the driving intention represented by the first control instruction to determine the state change.

[0127] The state change target refers to the state information that the vehicle should change to when it reaches the state corresponding to the first control command from its current state. The state change target includes one or more of the following: the vehicle's state change target in the X direction, the vehicle's state change target in the Y direction, and the vehicle's state change target in the Z direction.

[0128] For example, taking the manual driving mode as an example, when the first control instruction indicates that the vehicle's driving intention is to turn left at an angle A, when reaching the left turn angle A from the current state of the vehicle, the vehicle's acceleration in the X direction is required to be a, the lateral acceleration in the Y direction is required to be b, and the inclination angle in the Z direction is required to be c. Then, the vehicle's state change target in the X direction is to change the X-direction acceleration to a, the state change target in the Y direction is to change the Y-direction lateral acceleration to b, and the state change target in the Z direction is to change the Z-direction inclination angle to c.

[0129] After the state change target of the vehicle is obtained, the corresponding second control instruction can be sent to each control unit according to the state change target of the vehicle.

[0130] Exemplarily, the whole vehicle control target is determined based on the vehicle's state change target, and the wheel force vector of each wheel of the vehicle is obtained based on the whole vehicle control target. Based on the wheel force vector of each wheel, the wheel control target of each wheel in the X direction, Y direction, and Z direction is obtained, and the corresponding second control instruction is sent to each control unit based on the control target of each wheel.

[0131] The vehicle control target can be used to represent the vehicle force vector required to achieve the vehicle's state change target. After obtaining the vehicle's state change target, the cooperative control unit calculates the vehicle force vector based on the state change target. After obtaining the vehicle force vector, the cooperative control unit decomposes the vehicle force vector based on the actuation capabilities of each wheel in the X, Y, and Z directions to obtain the wheel force vector for each wheel. Based on each wheel's wheel force vector, the wheel control target for each wheel in the X, Y, and Z directions is then determined.

[0132] The wheel control targets of each wheel in the X-direction, Y-direction, and Z-direction may be used to represent the force vector required by each wheel in the X-direction, Y-direction, and Z-direction.

[0133] As an example, based on the vehicle dynamics model, the driving intent represented by the first control command is parsed to obtain a state change target. The state change target is calculated to obtain a vehicle force vector. Based on the vehicle force vector, the wheel force vector for each wheel is obtained. Based on the wheel force vector for each wheel, the wheel control target for each wheel is calculated based on the vehicle dynamics model. The description of the vehicle dynamics model can refer to conventional techniques and is not elaborated here.

[0134] After the wheel control target of each wheel is obtained, a corresponding second control instruction may be sent to each control unit according to the wheel control target of each wheel.

[0135] For example, for each wheel, the wheel control target in the X direction is controlled by the X-direction control unit, and therefore, a second control instruction can be sent to the X-direction control unit corresponding to the wheel. Correspondingly, the wheel control target in the Y direction is controlled by the Y-direction control unit, and therefore, a second control instruction can be sent to the Y-direction control unit corresponding to the wheel. The wheel control target in the Z direction is controlled by the Z-direction control unit, and therefore, a second control instruction can be sent to the Z-direction control unit corresponding to the wheel.

[0136] As shown in Figure 6, when the first control command indicates a light braking intention, the state change target derived from the first control command is a vehicle deceleration in the X direction of a, where a is less than a first predetermined threshold. Based on the state change target required for light braking, a wheel control target in the X direction is derived for each wheel. Each wheel's X-direction wheel control target can be achieved by the drive control unit controlling the motor drive mechanism to regenerate energy at each wheel.

[0137] Therefore, the cooperative control unit can send a second control instruction to the drive control unit indicating that the motor drive mechanism is controlled to perform energy recovery. For other control units, the cooperative control unit sends a second control instruction indicating that no control is provided, or there is no need to send a second control instruction.

[0138] After receiving the second control instruction, the drive control unit can control the motor corresponding to each wheel in the motor drive mechanism to reverse based on the second control instruction, and achieve light braking based on energy recovery.

[0139] As shown in Figure 7, when the first control instruction indicates that the driving intention of the vehicle is heavy braking, the state change target obtained based on the first control instruction is that the deceleration of the vehicle in the X direction is b, and b is greater than the second set threshold value. Based on the state change target required for heavy braking, the wheel control target of each wheel in the X direction is obtained. The wheel control target of each wheel in the X direction can be achieved by the drive control unit controlling the motor drive mechanism to recover energy for each wheel and the brake control unit controlling the brake mechanism to provide braking force for each wheel. Therefore, the cooperative control unit can send a second control instruction to the drive control unit that indicates the control of the motor drive mechanism to recover energy, and send a second control instruction to the brake control unit that indicates the control of the brake mechanism to provide braking force. For other control units, the cooperative control unit sends a second control instruction that indicates that no control is provided, or there is no need to send a second control instruction.

[0140] After receiving the second control instruction, the drive control unit can control the motor corresponding to each wheel in the motor drive mechanism to reverse the rotation to recover energy. After receiving the second control instruction, the brake control unit can control the brake mechanism to provide braking force to each wheel based on the second control instruction. In this way, the drive control unit and the brake control unit work together to achieve heavy braking.

[0141] The second set threshold is greater than or equal to the first set threshold. The first set threshold and the second set threshold can be set according to actual needs, and this application does not make specific restrictions. For example, the first set threshold is 3m / s 2 , the second threshold is set to 5m / s 2 .

[0142] In braking scenarios, when the cooperative control unit detects that the vehicle is decelerating in the X direction, if the deceleration is less than the first set threshold, it is considered light braking, and the drive control unit controls the motor drive mechanism to recover energy, thus achieving light braking. If the deceleration is greater than the second set threshold, it is considered heavy braking, and to improve vehicle stability and comfort, the drive control unit and the brake control unit can cooperate to achieve heavy braking.

[0143] As shown in Figure 8, when the first control command indicates that the vehicle's driving intention is a sharp turn, the state change targets derived from the first control command are: the vehicle's acceleration in the X direction changes to a, the lateral acceleration in the Y direction changes to b, and the tilt angle in the Z direction changes to c. Based on the state change targets required for the sharp turn, the wheel control targets in the X direction, Y direction, and Z direction are derived for each wheel. The wheel control targets in the X direction for each wheel can be achieved by the drive control unit controlling the motor drive mechanism to regenerate energy or output torque. The wheel control targets in the Y direction for the front wheels of the vehicle can be achieved by the front steering control unit controlling the front steering mechanism to steer the front wheels. The wheel control targets in the Y direction for the rear wheels of the vehicle can be achieved by the rear steering control unit controlling the rear steering mechanism to steer the rear wheels. The wheel control targets in the Z direction for each wheel can be achieved by the suspension control unit controlling the suspension mechanism to adjust the suspension height.

[0144] Therefore, the cooperative control unit can send a second control instruction to the front-wheel steering control unit indicating that the front-wheel steering mechanism is controlling the steering of the front wheels, send a second control instruction to the rear-wheel steering control unit indicating that the rear-wheel steering mechanism is controlling the steering of the rear wheels, send a second control instruction to the drive control unit indicating that the motor drive mechanism is controlling energy recovery and / or torque output, and send a second control instruction to the suspension control unit indicating that the suspension mechanism is controlling height adjustment. For other control units, the cooperative control unit sends a second control instruction indicating that no control is provided, or does not send a second control instruction.

[0145] After receiving the second control instruction, the front wheel steering control unit controls the front wheel steering mechanism to steer the front wheels according to the second control instruction. After receiving the second control instruction, the rear wheel steering control unit controls the rear wheel steering mechanism to steer the rear wheels according to the second control instruction.

[0146] After receiving the second control instruction, the drive control unit controls the operation of the motor in the motor drive mechanism according to the second control instruction, and performs energy recovery or torque output to each wheel.

[0147] For example, when turning left, the second control instruction received by the drive control unit includes an instruction to control the motor drive mechanism to recover energy for the left front wheel, and an instruction to control the motor drive mechanism to output torque to the right front wheel. Upon receiving the second control instruction, the drive control unit can control the motor corresponding to the left front wheel in the motor drive mechanism to reverse-tow for energy recovery, and control the motor corresponding to the right front wheel in the motor drive mechanism to output torque to provide torque to the right front wheel. By applying different torques to different vehicles, a steering effect is achieved.

[0148] After receiving the second control instruction, the suspension control unit can control the suspension mechanism to adjust the suspension height according to the second control instruction. The drive control unit and the suspension control unit cooperate in a sharp turn, so that the vehicle can maintain balance in a sharp turn.

[0149] As an example, the cooperative control unit may call the control interface of each control unit, and send the second control instruction to each control unit based on the control interface of each control unit.

[0150] The embodiment of the present application decomposes the first control instruction through the cooperative control unit to obtain second control instructions corresponding to multiple control units. Through the coordinated cooperation of multiple control units, the vehicle posture can be better controlled, the vehicle operation can be smoother, and the user experience can be more comfortable.

[0151] In order to further improve the comfort and stability of vehicle operation, in an embodiment of the present application, the step of sending a corresponding second control instruction to each control unit according to the state change target may also include step (A) and step (B).

[0152] (A) Obtain vehicle status data and adjust the vehicle's status change target based on the vehicle status data.

[0153] As an example, the vehicle status data includes one or more of the following: vehicle operation mode data, vehicle body posture parameters, and environmental parameters of the vehicle's environment.

[0154] The vehicle is equipped with multiple operating modes to adjust the vehicle's power output. That is, the vehicle's power output varies in different operating modes. For example, the operating modes configured on the vehicle include Economy Mode, Sport Mode, and Comfort Mode. In Sport Mode, the vehicle's power output is maximized, but this will increase vehicle energy consumption to a certain extent. In Economy Mode, the vehicle prioritizes energy conservation, thereby limiting some power output. In Comfort Mode, the vehicle's suspension is softer, the steering wheel is lighter, and the power output is lower.

[0155] It can be understood that the operating modes listed above are merely examples of the operating modes configured on the vehicle in the embodiments of the present application and are not intended to be limiting.

[0156] The vehicle body posture parameters include the current vehicle speed, acceleration in the XYZ directions, etc. The environmental parameters include the slope of the road the vehicle is currently traveling on, the curve coefficient, the adhesion coefficient, etc.

[0157] As an example, when adjusting the state change target according to the environmental parameters, a corresponding adjustment value can be obtained according to the environmental parameters, and the state change target can be adjusted according to the adjustment value.

[0158] Taking the adjustment of the vehicle's state change target (acceleration change target) in the X direction by the slope as an example, different slopes correspond to different acceleration adjustment values. When adjusting according to the slope, the corresponding acceleration adjustment value can be obtained based on the current slope, and then the acceleration target in the X direction can be adjusted based on the acceleration adjustment value. For example, if the uphill slope is A and the corresponding adjustment value is a1, then a1 can be added to the acceleration target in the X direction. For another example, if the downhill slope is B and the corresponding adjustment value is b1, then b1 can be subtracted from the acceleration target in the X direction.

[0159] For example, adjusting the vehicle's Z-direction state change target (roll angle change target) using the curve coefficient is described. Different curve coefficients correspond to different roll angle adjustment values. When adjusting based on the curve coefficient, the corresponding roll angle adjustment value is obtained based on the current curve coefficient. The Z-direction roll angle is then adjusted based on this adjustment value, i.e., the roll angle in the Z direction is added to the adjustment value.

[0160] In the embodiments of the present application, the smaller the adhesion coefficient, the slower the vehicle's state changes in the X and Y directions need to be to improve vehicle safety. The example of adjusting the vehicle's state change targets in the X and Y directions based on the adhesion coefficient is used for illustration. Different adhesion coefficients correspond to different adjustment values. When adjusting based on the adhesion coefficient, a corresponding adjustment value is obtained based on the current adhesion coefficient. Then, based on the adjustment value, the vehicle's state change targets in the X and Y directions are adjusted. Specifically, the adjustment value is added to the X and Y state change targets.

[0161] As an example, when adjusting the vehicle's state change target based on the vehicle's operating mode data, the vehicle's current operating mode can be obtained based on the vehicle's operating mode data, and the vehicle's state change target can be adjusted based on the vehicle's current operating mode.

[0162] For example, when the vehicle's operating mode data indicates that the vehicle's current operating mode is comfort mode, the corresponding mode information is that the vehicle's current power output capability is low, and therefore the vehicle's acceleration target in the X direction may be reduced.

[0163] When the vehicle's operating mode data indicates that the vehicle's current operating mode is a sports mode and the vehicle's current power output capability is relatively high, the vehicle's state change target may not be adjusted.

[0164] When the vehicle's operating mode data indicates that the vehicle's current operating mode is an economic mode and the vehicle's current power output capacity is low, the vehicle's state change target may be lowered.

[0165] As an example, when adjusting the state change target of the vehicle according to the posture parameters of the vehicle body, the vehicle's stable state information can be determined based on the posture parameters of the vehicle body, and the vehicle's state change target can be adjusted based on the vehicle's stable state information.

[0166] When the vehicle's stability information indicates that the vehicle's posture is at a stability boundary, meaning it's vulnerable to instability, the vehicle's state change target can be adjusted to stabilize the vehicle's posture and improve vehicle safety. For example, if the vehicle's stability information indicates that the vehicle's posture is tilted in the Y direction and is prone to lane deviation, the vehicle's state change target in the Y direction can be adjusted to maintain stability in that direction.

[0167] When the stable state information of the vehicle indicates that the vehicle's body posture is in a stable state, the vehicle's state change target may not be adjusted.

[0168] It is understandable that the above is only an example of adjusting the state change target of the vehicle according to the vehicle state data in the embodiment of the present application, and is not intended to be limiting. In some examples, there may be other implementations. For example, the state change target of the vehicle may be adjusted according to the priority of the vehicle state data. Exemplarily, the state change target of the vehicle is first corrected according to the environmental parameters to obtain a first state change target, and then the first state change target is corrected according to the vehicle's operating mode data to obtain a second state change target. Thereafter, the second state change target is corrected according to the posture parameters of the vehicle body to obtain the adjusted state change target. It is specifically set according to actual needs.

[0169] (B) Based on the adjusted state change target, a corresponding second control instruction is sent to each control unit.

[0170] After obtaining the adjusted state change target, the vehicle control target is determined based on the adjusted state change target. Based on the vehicle control target, the wheel force vector for each wheel of the vehicle is obtained. Based on the wheel force vector for each wheel, the wheel control target for each wheel in the X, Y, and Z directions is obtained. Based on the control target for each wheel, a corresponding second control instruction is sent to each control unit. The specific process can be found in the above description and is not detailed here.

[0171] The embodiments of the present application adjust and optimize the vehicle's state change target based on vehicle state data, thereby improving the smoothness and safety of vehicle operation when controlling vehicle operation based on the optimized state change target. Even in the event of a tire blowout, the system can dynamically output second control instructions adapted to each control unit based on changes in vehicle state data such as body posture parameters, maintaining a stable vehicle state.

[0172] As shown in Figure 9, when the cooperative control unit detects that the vehicle is unbalanced due to a tire blowout, it can calculate a new state change target based on the acquired vehicle state data. According to the state change target, one or more control units among the front wheel steering control unit, rear wheel steering control unit, drive control unit, and suspension control unit are coordinated to control the vehicle so that the vehicle can quickly maintain a new balance. Among them, the front wheel steering control unit can control the front wheel steering through the front wheel steering mechanism, and the rear wheel control unit can control the rear wheel steering through the rear wheel steering mechanism. The drive control unit can provide different torques to each wheel through the motor drive mechanism, and produce a steering effect through the torque difference between different wheels. The suspension control unit can control the suspension mechanism to adjust the suspension height.

[0173] Considering that in actual application, if a component, such as a control unit or an execution unit, fails, it may cause the vehicle to lose balance. In order to enable the vehicle to quickly restore balance when a component fails, in an embodiment of the present application, the cooperative control unit is provided with a redundancy mechanism. When a control unit or an execution unit is found to have failed, the capacity of the failed unit can be compensated by other control units or execution units. As shown in Figure 10, the cooperative control unit can also obtain the usage status of each control unit and the usage status of the execution unit corresponding to each control unit, and send a corresponding second control instruction to each control unit in combination with the usage status of each control unit and the usage status of the execution unit corresponding to each control unit.

[0174] Based on this, in an embodiment of the present application, the step of sending a corresponding second control instruction to each control unit according to the state change target may also include step (a) and step (b).

[0175] (a) Obtain the usage status of each control unit and the usage status of the execution unit corresponding to each control unit.

[0176] The control unit's usage status indicates whether the control unit has failed. If a control unit fails, the control unit's usage status is unavailable; if the control unit is not failing, the control unit's usage status is normal. Similarly, the execution unit's usage status indicates whether the execution unit has failed. If a failure occurs, the execution unit's usage status is unavailable; if the failure occurs, the execution unit's usage status is normal.

[0177] As an example, a heartbeat detection mechanism is provided between the cooperative control unit and each control unit, and a heartbeat detection mechanism is also provided between each control unit and its corresponding execution unit. Each control unit can obtain the usage status of the corresponding execution unit through the heartbeat detection mechanism. The cooperative control unit can obtain the usage status of the control unit and the usage status of the execution unit corresponding to the control unit through the heartbeat detection mechanism.

[0178] For example, the control unit can send usage status information to the cooperative control unit according to a set time period, and the usage status information includes its own usage status and the usage status of the corresponding execution unit. When the cooperative control unit receives the usage status information sent by the control unit within the current time period, the usage status of the control unit and the usage status of the corresponding execution unit can be obtained based on the usage status information. Among them, the usage status of the control unit is normal use, and the usage status of the execution unit is determined according to the detection result of the control unit. When the cooperative control unit does not receive the usage status information sent by the control unit within the current time period, it can be obtained that the usage status of the control unit is unusable, and the usage status of the execution unit corresponding to the control unit is also unusable.

[0179] For example, the cooperative control unit can also send a usage status query command to the control unit. If the cooperative control unit receives the usage status information fed back by the control unit in accordance with the usage status query command, it can obtain the usage status of the control unit and the usage status of the corresponding execution unit. If the cooperative control unit does not receive the usage status information fed back by the control unit in accordance with the usage status query command, it can be determined that the usage status of the control unit is unusable, and the usage status of the execution unit corresponding to the control unit is also unusable.

[0180] The above is only an example of obtaining the usage status of the control unit and the usage status of the execution unit corresponding to the control unit in the embodiment of the present application, and is not intended to be limiting. It is set according to actual needs.

[0181] (b) Sending a corresponding second control instruction to each control unit according to the state change target, the usage state of each control unit, and the usage state of the execution unit corresponding to each control unit.

[0182] For example, the cooperative control unit may first obtain a wheel control target based on the state change target. Then, based on the wheel control target, the usage status of the control unit, and the usage status of the execution unit corresponding to the control unit, it may obtain control information for each control unit. Based on the control information from each control unit, the cooperative control unit may send a second control instruction to each control unit.

[0183] The cooperative control unit can determine whether a faulty control unit and / or execution unit exists based on the usage status of each control unit and the usage status of the execution unit corresponding to each control unit. If no faulty control unit or execution unit is detected, the cooperative control unit sends a second control instruction to each control unit based on the wheel control target of each wheel and the capabilities of each control unit.

[0184] If a faulty control unit and / or execution unit is found, the capabilities of the faulty control unit and / or execution unit can be compensated by other healthy control units, and after compensation, a second control instruction is sent to the control unit.

[0185] For example, let's take a braking failure as an example. As shown in Figure 11, in a braking scenario, the wheel control target for each wheel in the X direction can be derived based on the state change target. This wheel control target can be achieved by the drive control unit controlling the motor drive mechanism for energy recovery and the brake control unit controlling the brake mechanism for braking force.

[0186] When it is found that the braking control unit and / or the braking mechanism fails, that is, the braking control unit cannot control the braking mechanism to provide braking force, the cooperative control unit can distribute the braking force provided by the braking control unit and the corresponding braking mechanism to the drive control unit, and the drive control unit compensates for it. That is, when the braking control unit and / or the braking mechanism fails, the drive control unit can control the motor drive mechanism to achieve braking by energy recovery. Therefore, the cooperative control unit can send a second control instruction to the drive control unit, which indicates that the motor drive mechanism is controlled to perform energy recovery, and send a second control instruction to the braking control unit and other control units, which indicates that no control is provided, or no second control instruction is sent. After receiving the second control instruction, the drive control unit can control the reverse drag of the motor in the motor drive mechanism based on the second control instruction, and use energy recovery to achieve braking.

[0187] Take the front wheel steering failure as an example. As shown in Figure 12, in a turning scenario, the wheel control target for each wheel in the X direction, the wheel control target for the Y direction, and the wheel control target for the Z direction can be obtained based on the state change target. The wheel control target for each wheel in the X direction can be achieved by the drive control unit controlling the motor drive mechanism to recover energy or output torque. The wheel control target for the front wheel of the vehicle in the Y direction can be achieved by the front wheel steering control unit controlling the front wheel steering mechanism to steer the front wheel. The wheel control target for the rear wheel of the vehicle in the Y direction can be achieved by the rear wheel steering control unit controlling the rear wheel steering mechanism to steer the rear wheel. The wheel control target for each wheel in the Z direction can be achieved by the suspension control unit controlling the suspension mechanism to adjust the suspension height.

[0188] When the front wheel steering control unit and / or the forward steering mechanism fails, the front wheel steering control unit cannot control the front wheel steering mechanism to achieve the wheel control target of the vehicle's front wheels in the Y direction. The cooperative control unit can distribute the wheel control target of the vehicle's front wheels in the Y direction to one or more of the drive control unit, the rear wheel steering control unit, the braking control unit and the suspension control unit, and compensated by one or more of the drive control unit, the rear wheel steering control unit, the braking control unit and the suspension control unit.

[0189] Therefore, the cooperative control unit can send a second control instruction to the drive control unit, the rear-wheel steering control unit, the braking control unit and the suspension control unit, and send a second control instruction to the front-wheel steering control unit and other control units, indicating that no control is provided, or not send a second control instruction.

[0190] As an example, since the drive control unit, rear-wheel steering control unit, and suspension control unit each have their own control targets, after assigning the wheel control targets for the vehicle's front wheels in the Y direction to these control units, the wheel control targets are accumulated on top of the control targets of the drive control unit, rear-wheel steering control unit, and suspension control unit. The specific assignment of the wheel control targets for the vehicle's front wheels in the Y direction can be implemented based on the vehicle dynamics model and is not detailed here.

[0191] In an embodiment of the present application, the drive control unit can control the motor drive mechanism to provide different torques to different wheels, generating a steering effect through the torque differences between the different wheels. The brake control unit can control the braking force provided by the brake mechanism to different wheels, generating a steering effect through the braking force differences between the different wheels. The suspension control unit can control the suspension mechanism to adjust the suspension height, changing the load-bearing capacity of each wheel, and offsetting the vehicle center based on the load-bearing capacity differences between the wheels to generate a steering effect.

[0192] For example, when a vehicle turns left, if the front-wheel steering control unit and / or forward steering mechanism malfunctions, the wheel control targets in the Y direction for the front wheels can be compensated for using wheel force differences in the X direction, force differences in the Z direction, and / or steering differences in the Y direction for the rear wheels. The wheel force difference in the X direction can be achieved by applying braking force to the left front wheel and driving force to the right front wheel, thereby creating a left turn effect through the force difference between the left and right front wheels in the X direction. The force difference in the Z direction can be achieved by adjusting the suspension height so that the load capacity of the right wheels is less than that of the left wheels, lifting the outer side of the vehicle and shifting the center of gravity to the left, thus creating a left turn effect. The steering difference in the Y direction for the rear wheels can be achieved by applying different steering forces to the left and right rear wheels, so that the steering force of the right rear wheel is greater than that of the left rear wheel, thus achieving a left turn effect.

[0193] The cooperative control unit in the embodiment of the present application obtains the usage status of the control unit and the execution unit, and obtains the second control instruction of the control unit based on the usage status of the control unit and the execution unit. Therefore, when the control unit and / or the execution unit fails, the relevant capabilities can be supplemented by other control units to make the vehicle controllable and improve the safety of the vehicle.

[0194] To further improve vehicle controllability, in some examples, a backup cooperative control unit can be set up for the cooperative control unit. In the event of a failure of the cooperative control unit, the backup cooperative control unit can provide the capabilities of the cooperative control unit. As shown in Figure 13, in the event of a failure of the cooperative control unit, the backup cooperative control unit will coordinate control of the front-wheel steering control unit, rear-wheel steering control unit, drive control unit, suspension control unit, and other control units. To save costs, the backup cooperative control unit can be lower than the cooperative control unit in terms of limited computing power and reserved computing power.

[0195] In order to further save hardware costs, in an embodiment of the present application, as shown in FIG14 , the control unit can also directly receive the first control instruction and control the corresponding execution unit to perform the corresponding operation according to the first control instruction.

[0196] Based on this, please refer to Figure 15, which is a second interactive schematic diagram of the vehicle control method provided in an embodiment of the present application. The vehicle control method shown in Figure 15 can be applied to the control unit in Figure 3. The vehicle control method shown in Figure 15 is described below using a control unit as an example.

[0197] S301, the control unit receives a first control instruction and / or a second control instruction from the cooperative control unit; wherein the second control instruction is sent by the cooperative control unit to the control unit after receiving the first control instruction.

[0198] In an embodiment of the present application, the control unit is connected to the autonomous driving control unit and the human-machine interaction device. By connecting the control unit to the autonomous driving control unit and the human-machine interaction device, the control unit can receive a first control instruction from the autonomous driving control unit or the human-machine interaction device. The connection between the control unit, the autonomous driving control unit, and the human-machine interaction device can be a communication connection or an electrical connection. This application does not limit the connection method and is set according to actual needs.

[0199] In the embodiment of the present application, the control unit is connected to the cooperative control unit, and therefore, the control unit can also receive the second control instruction from the cooperative control unit.

[0200] In order to ensure that the vehicle remains controllable when the cooperative control unit fails, thereby improving the safety of vehicle operation, in an embodiment of the present application, when the cooperative control unit fails, the control unit receives a first control instruction from the automatic driving control unit, or a first control instruction from the human-computer interaction device, and controls the vehicle operation according to the first control instruction. When the cooperative control unit is not faulty, the control unit receives a second control instruction from the cooperative control unit.

[0201] The following uses the first autonomous driving mode as an example. As shown in Figure 16, when the auxiliary control unit is not faulty, the autonomous driving control unit can directly send a first control instruction to the auxiliary control unit. Based on the first control instruction, the auxiliary control unit determines a second control instruction for the control unit and sends the second control instruction to the control unit, so that the control unit can receive the second control instruction from the auxiliary control unit. However, if the auxiliary control unit fails, the autonomous driving control unit can directly send the first control instruction to the control unit, so that the control unit can receive the first control instruction from the autonomous driving control unit.

[0202] In an embodiment of the present application, a heartbeat detection mechanism is provided between the autonomous driving control unit and the auxiliary control unit. The autonomous driving control unit can detect whether the auxiliary control unit has failed based on the heartbeat detection mechanism. For example, upon receiving status information from the auxiliary control unit, the autonomous driving control unit sends a first control instruction to the auxiliary control unit, and upon not receiving status information from the auxiliary control unit, sends the first control instruction to the control unit.

[0203] For example, the auxiliary control unit may send status information to the automatic driving control unit at a preset time period. When the automatic driving control unit receives status information from the auxiliary control unit within the current time period, it determines that the auxiliary control unit is not faulty and then sends a first control instruction to the auxiliary control unit. When the automatic driving control unit does not receive status information from the auxiliary control unit, it determines that the auxiliary control unit is faulty and then sends the first control instruction to the control unit.

[0204] For another example, the autonomous driving control unit may also issue a first status query instruction to the auxiliary control unit. When the autonomous driving control unit receives status information fed back by the auxiliary control unit in accordance with the first status query instruction, it determines that the auxiliary control unit has not failed, and then sends the first control instruction to the auxiliary control unit. If the autonomous driving control unit does not receive status information fed back by the auxiliary control unit in accordance with the first status query instruction, it determines that the auxiliary control unit has failed, and then sends the first control instruction to the control unit.

[0205] The above is only an example of the embodiment of the present application for the automatic driving control unit to detect whether the auxiliary control unit has a fault. It is not intended to be limiting and is set according to actual needs.

[0206] To reduce vehicle control latency in emergency situations, that is, in scenarios with high latency requirements, the autonomous driving control unit can also directly send a first control instruction to the control unit, even if the cooperative control unit is not faulty, thereby reducing vehicle control latency. For example, when the autonomous driving control unit identifies a collision risk, it sends the first control instruction to the control unit. The control unit can then directly control the vehicle according to the first control instruction, reducing vehicle control latency and improving vehicle operation safety.

[0207] In some examples, the autonomous driving control unit can also send a first control instruction to both the control unit and the cooperative control unit. The specific configuration can be based on actual needs, and the embodiments of this application do not impose specific restrictions.

[0208] Accordingly, as shown in Figure 17, for the second autonomous driving mode, when the auxiliary control unit is not faulty, the autonomous driving control unit can directly send a first control instruction to the auxiliary control unit. Based on the first control instruction, the auxiliary control unit determines a second control instruction for the control unit and sends the second control instruction to the control unit, so that the control unit can receive the second control instruction from the auxiliary control unit. If the auxiliary control unit fails, the autonomous driving control unit can directly send the first control instruction to the control unit, so that the control unit can receive the first control instruction from the autonomous driving control unit.

[0209] The following uses the manual driving mode as an example for explanation. As shown in Figure 18, in the manual driving mode, when the cooperative control unit is not faulty, the human-machine interaction device sends a first control instruction to the cooperative control unit and the control unit. The cooperative control unit determines the second control instruction of the control unit based on the first control instruction and sends the second control instruction to the control unit. Then, the control unit will receive the second control instruction from the cooperative control unit and the first control instruction from the human-machine interaction device. When the cooperative control unit fails, the human-machine interaction device will also send the first control instruction to the cooperative control unit and the control unit. However, due to the failure of the cooperative control unit, the cooperative control unit cannot determine the second control instruction of the control unit based on the first control instruction. Then, the control unit will only receive the first control instruction from the human-machine interaction device.

[0210] Among them, the process of the cooperative control unit sending the corresponding second control instruction to the control unit according to the first control instruction can refer to the above description and will not be repeated here.

[0211] S302: The control unit controls the corresponding execution unit to perform a corresponding action according to the first control instruction or the second control instruction.

[0212] To improve vehicle operating comfort, the control unit can control the corresponding execution unit to perform corresponding actions based on the received second control instruction if the cooperative control unit is not faulty. If the cooperative control unit fails, the control unit controls the corresponding execution unit to perform corresponding actions based on the received first control instruction to ensure vehicle controllability and improve vehicle safety.

[0213] Considering that in some scenarios, the control unit may receive a first control instruction and a second control instruction from the cooperative control unit. For example, in manual driving mode, when the cooperative control unit is not faulty, the control unit may receive both the first and second control instructions. To facilitate control by the control unit, in embodiments of the present application, the control unit may select instructions to control the execution unit based on the status of the cooperative control unit.

[0214] As shown in Figure 19, in an embodiment of the present application, when the control unit receives status information from the cooperative control unit, it controls the corresponding execution unit to perform the corresponding action according to the second control instruction; and when the status information is not received from the cooperative control unit, it controls the corresponding execution unit to perform the corresponding action according to the received first control instruction.

[0215] For example, the cooperative control unit may send status information to the control unit at a preset time period. When the control unit receives status information from the cooperative control unit within the current time period, it determines that the cooperative control unit has not failed, and then controls the corresponding execution unit to perform the corresponding action according to the second control instruction. When the control unit does not receive status information from the cooperative control unit, it determines that the cooperative control unit has failed, and then controls the corresponding execution unit to perform the corresponding action according to the received first control instruction.

[0216] For another example, the control unit may also issue a second status query instruction to the cooperative control unit. When the control unit receives status information fed back by the cooperative control unit in accordance with the second status query instruction, it determines that the cooperative control unit has not failed, and then controls the corresponding execution unit to perform the corresponding action according to the second control instruction. If the control unit does not receive status information fed back by the cooperative control unit in accordance with the second status query instruction, it determines that the cooperative control unit has failed, and then controls the corresponding execution unit to perform the corresponding action according to the received first control instruction.

[0217] By improving the communication topology between various units, the embodiments of the present application enable the control unit to still receive the first control instruction when a failure occurs in the cooperative control unit, and to control the execution unit to perform the corresponding action according to the first control instruction, thereby ensuring the operation of the vehicle and improving the safety of vehicle operation. As shown in Figure 20, when a failure occurs in the cooperative control unit, the front-wheel steering control unit, rear-wheel steering control unit, drive control unit, suspension control unit, and other control units directly receive instructions from the autonomous driving control unit or the human-computer interaction device, and control the execution unit to perform the corresponding action according to the first control instruction.

[0218] To further improve the safety and controllability of vehicle operation, as shown in Figure 21, in an embodiment of the present application, when the control unit is unable to receive either the first control instruction or the second control instruction from the cooperative control unit, that is, when both the autonomous driving control unit and the human-machine interface device are unable to output the first control instruction, the control unit will control the corresponding execution unit to perform the corresponding action according to the preset strategy. Specifically, when both the autonomous driving control unit and the human-machine interface device are unable to output the first control instruction, the vehicle's driving mode is the risk emergency mode.

[0219] As an example, a heartbeat detection mechanism also exists between the control unit and the autonomous driving control unit. The control unit can use this mechanism to detect whether the autonomous driving control unit has failed. For details, please refer to the process described above where the control unit detects whether the cooperative control unit has failed through the heartbeat detection mechanism. This is not detailed here.

[0220] When the control unit detects a fault in the autonomous driving control unit and does not receive the first control command output by the human-machine interaction device within a preset time period, the control unit controls the corresponding execution unit to perform the corresponding action according to the preset strategy. The preset time period can be set according to actual needs and is not specifically limited in this embodiment of the application. Different control units can be configured with different strategies.

[0221] As shown in Figure 22, in risk emergency mode, the drive control unit is configured to perform energy recovery according to the first ratio, and the brake control unit is configured to perform braking according to the second ratio. The first and second ratios are preset static values ​​and can be set according to actual needs. In risk emergency mode, the front steering control unit is configured to automatically return to the center, and the rear steering control unit is configured to automatically return to the center. In risk emergency mode, the suspension control unit is configured to automatically return to the default height.

[0222] In the embodiment of the present application, the strategy configured by each control unit can be set according to actual needs and is not specifically limited.

[0223] The embodiment of the present application configures a strategy for the control unit so that when abnormalities occur in both automatic driving and manual driving, the vehicle can still be controlled, and the vehicle stability can be maintained to the maximum extent, and the brakes can be applied, thereby reducing the occurrence of vehicle accidents and improving vehicle safety.

[0224] The embodiment of the present application provides a multi-level heterogeneous redundant architecture, including driving mode redundancy, cooperative control unit redundancy, control unit single function redundancy, and control unit static configuration control redundancy. Among them, driving mode redundancy includes switching to manual driving in case of failure of automatic driving. In case of failure of manual driving, automatic driving supplements risk control to improve the safety of vehicle operation. Co-control unit redundancy includes that when a control unit and / or execution unit fails, other control units can be used to supplement related capabilities, so that the vehicle can be controlled and the safety of the vehicle is improved. Control unit single function redundancy includes that when a failure occurs in the cooperative control unit, the control unit can directly receive the first control instruction, complete the basic control function based on the first control instruction, and maintain the stability of the vehicle. Control unit static configuration control redundancy includes that when an abnormality occurs in automatic driving or manual driving, the control unit can control the execution unit to perform corresponding actions according to the configured strategy, which can maximize the stability of the vehicle or brake.

[0225] The embodiment of the present application improves the redundancy capability of the vehicle system by improving the communication topology between the units and building a multi-level heterogeneous redundant architecture through software configuration and dynamic adaptation algorithms without adding new hardware. This ensures that the vehicle remains controllable in various failure scenarios, improves the safety of vehicle operation, reduces hardware equipment costs, and avoids common cause failures.

[0226] Please refer to Figure 23, which is a structural diagram of a controller 300 provided in an embodiment of the present application. The controller 300 shown in Figure 23 is, for example, the control unit in the corresponding embodiments in Figures 3, 5, and 15 above. As shown in Figure 23, the controller 300 includes a first instruction receiving module 301 and a control module 302; the first instruction receiving module 301 is used to receive a first control instruction and / or a second control instruction from the cooperative control unit; the second control instruction is sent by the cooperative control unit to the control unit after receiving the first control instruction; the control module 302 is used to control the corresponding execution unit to perform corresponding actions according to the first control instruction or the second control instruction.

[0227] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and brevity of description, the specific working process of the controller 300 described above can refer to the corresponding process in the aforementioned method embodiment and will not be repeated here.

[0228] Please refer to Figure 24, which is a schematic diagram of the structure of the controller 400 provided in an embodiment of the present application. The controller 400 shown in Figure 24 is, for example, the cooperative control unit in the corresponding embodiments in Figures 3, 5, and 15 above. As shown in Figure 24, the controller 400 includes a second instruction receiving module 401, a processing module 402, and an instruction sending module 403. The second instruction receiving module 401 is used to receive a first control instruction; the processing module 402 is used to obtain a second control instruction for each control unit based on the first control instruction; and the instruction sending module 403 is used to send a second control instruction to each control unit.

[0229] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and brevity of description, the specific working process of the controller 400 described above can refer to the corresponding process in the aforementioned method embodiment and will not be repeated here.

[0230] Please refer to Figure 25, which is a structural diagram of an electronic device 500 provided in an embodiment of the present application. Among them, the electronic device 500 shown in Figure 25 can be used to execute the steps performed by any one of the control unit, cooperative control unit, automatic driving control unit, and mode switching unit described in the above embodiments. Although the electronic device 500 shown in Figure 25 shows certain specific features, those skilled in the art will realize from the embodiments of the present application that, for the sake of brevity, various other features are not shown in Figure 25 to avoid confusing more relevant aspects of the implementation methods disclosed in the embodiments of the present application.

[0231] As shown in Figure 25, electronic device 500 includes a processor 501, a memory 502, and a network interface 503. The processor 501, the memory 502, and the network interface 503 are connected via a double data rate (DDR) bus or other types of buses. The network interface 503 is used to communicate with other devices, for example, to receive information sent by other devices via the network interface 503.

[0232] Processor 501 may be a central processing unit (CPU) or other specific integrated circuit. Processor 501 may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. In practical applications, electronic devices may also include multiple processors, each of which may include one or more processor cores.

[0233] Memory 502 is typically used to store computer program executable code. Executable code includes instructions. Processor 501 executes the instructions stored in memory to execute various functional applications and data processing of electronic device 500. Memory 502 includes a program storage area and a data storage area. The program storage area can store the operating system, at least one application required for a function, and the data storage area can store data generated during the use of electronic device 500.

[0234] In addition, the memory 502 may include a high-speed random access memory and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.

[0235] It is understood that the structure shown in FIG. 25 of the present application does not constitute a specific limitation on the electronic device 500. In other embodiments of the present application, the electronic device 500 may include more or fewer components than shown, or may combine or separate certain components, or may have different component arrangements, and the components may be implemented in hardware, software, or a combination of software and hardware.

[0236] In addition, an embodiment of the present application also provides a vehicle, including the above-mentioned vehicle heterogeneous redundancy device.

[0237] In addition, an embodiment of the present application also provides a vehicle, including one or more of the above-mentioned controller 300 and controller 400.

[0238] In addition, an embodiment of the present application further provides a computer-readable storage medium, on which computer program instructions are stored. When the computer program instructions are executed by a processing circuit, the functions or steps in the above method are implemented.

[0239] In addition, an embodiment of the present application also provides a chip system, which includes a processing circuit and a storage medium, wherein the storage medium stores computer program instructions; when the computer program instructions are executed by the processing circuit, the functions or steps in the above method are implemented.

[0240] In addition, an embodiment of the present application also provides a computer program product containing instructions, which, when the computer program product is run on a computer, enables the computer to perform the functions or steps in the above method.

[0241] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and conciseness of description, the chip system, vehicle heterogeneous redundant device, computer-readable storage medium, computer program product containing instructions, and specific working process of the vehicle described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0242] It is understandable that the steps of the method or algorithm described in conjunction with the embodiments of the present application can be implemented in a hardware manner, or can be implemented by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory, a flash memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a read-only optical disc, or any other form of storage medium. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and can write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an application specific integrated circuit (ASIC). In addition, the ASIC can be located in an electronic device. Of course, the processor and the storage medium can also be present in an electronic device as discrete components.

[0243] In an optional manner, when software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is implemented in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a digital video disk (DVD)), or a semiconductor medium (e.g., a solid state disk (SSD)).

[0244] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A vehicle heterogeneous redundancy device, characterized in that: It includes a co-control unit, one or more control units, and one or more execution units, wherein each control unit controls at least one execution unit; The control unit is configured to receive a first control instruction and / or a second control instruction from the co-control unit; wherein the second control instruction is sent by the co-control unit to the control unit after receiving the first control instruction; The control unit is used to control the corresponding execution unit to perform corresponding actions according to the first control instruction or the second control instruction.

2. The vehicle heterogeneous redundancy device according to claim 1, characterized in that: The vehicle heterogeneous redundant device also includes an automatic driving control unit; the automatic driving control unit is configured to send the first control instruction to the cooperative control unit when receiving status information from the cooperative control unit, and send the first control instruction to the control unit when not receiving status information from the cooperative control unit.

3. The vehicle heterogeneous redundancy device according to claim 2, characterized in that: The status information is fed back by the cooperative control unit after receiving the first status query instruction sent by the automatic driving control unit.

4. The vehicle heterogeneous redundancy device according to claim 2, characterized in that: The automatic driving control unit is further configured to send the first control instruction to the control unit when it is identified that the vehicle is at risk of collision.

5. The vehicle heterogeneous redundancy device according to any one of claims 1 to 4, characterized in that: The control unit is used to control the corresponding execution unit to perform a corresponding action according to the second control instruction when status information is received from the cooperative control unit, and to control the corresponding execution unit to perform a corresponding action according to the received first control instruction when status information is not received from the cooperative control unit.

6. The vehicle heterogeneous redundancy device according to claim 5, characterized in that: The status information is fed back by the cooperative control unit after receiving the second status query instruction sent by the control unit.

7. The vehicle heterogeneous redundancy device according to any one of claims 1 to 6, characterized in that: The cooperative control unit is used to obtain a state change target of the vehicle according to the first control instruction; and send a corresponding second control instruction to each of the control units according to the state change target.

8. The vehicle heterogeneous redundancy device according to claim 7, characterized in that: The cooperative control unit is used to obtain vehicle status data; adjust the state change target according to the vehicle status data to obtain an adjusted state change target; and send a corresponding second control instruction to each control unit according to the adjusted state change target.

9. The vehicle heterogeneous redundancy device according to claim 7 or 8, characterized in that: The cooperative control unit obtains the usage status of each control unit and the usage status of the execution unit corresponding to each control unit; and sends corresponding second control instructions to each control unit according to the state change target, the usage status of each control unit and the usage status of the execution unit corresponding to each control unit.

10. The vehicle heterogeneous redundancy device according to any one of claims 1 to 9, characterized in that: The vehicle heterogeneous redundancy device further includes a mode switching unit, which is configured to switch a driving mode of the vehicle.

11. The vehicle heterogeneous redundancy device according to claim 10, characterized in that: The driving modes of the vehicle include a manual driving mode, a first automatic driving mode, a second automatic driving mode, and a risk emergency mode; the mode switching unit is used to: When the vehicle is in the first automatic driving mode, if an abnormality occurs in the first automatic driving mode and the manual driving mode is not started normally, switching the first automatic driving mode to the second automatic driving mode; or When the vehicle is in the manual driving mode, if an abnormality occurs in the manual driving mode, the manual driving mode is switched to the second automatic driving mode; or, When an abnormality occurs in the manual driving mode, the first automatic driving mode, or the second automatic driving mode, switch to the risk emergency mode.

12. The vehicle heterogeneous redundancy device according to claim 11, characterized in that: The control unit is used to control the corresponding execution unit to perform corresponding actions according to a preset strategy when the driving mode of the vehicle is the risk emergency mode.

13. A vehicle control method, characterized in that: A control unit used in a vehicle heterogeneous redundant device according to any one of claims 1 to 12, the method comprising: The control unit receives a first control instruction and / or a second control instruction from the co-control unit; wherein the second control instruction is sent by the co-control unit to the control unit after receiving the first control instruction; The control unit controls the corresponding execution unit to perform corresponding actions according to the first control instruction or the second control instruction.

14. The vehicle control method according to claim 13, characterized in that: The control unit controls the corresponding execution unit to perform a corresponding action according to the first control instruction or the second control instruction, including: When the control unit receives the status information from the cooperative control unit, the control unit controls the corresponding execution unit to perform a corresponding action according to the second control instruction; When the control unit does not receive the status information from the cooperative control unit, the control unit controls the corresponding execution unit to perform a corresponding action according to the received first control instruction.

15. The vehicle control method according to claim 14, characterized in that: The status information is fed back by the cooperative control unit after receiving the second status query instruction sent by the control unit.

16. The vehicle control method according to any one of claims 13 to 15, characterized in that: The method further comprises: When the driving mode of the vehicle is the risk emergency mode, the control unit controls the corresponding execution unit to perform corresponding actions according to a preset strategy.

17. A vehicle control method, characterized in that: The method applied to the cooperative control unit in the vehicle heterogeneous redundant device according to any one of claims 1 to 12 includes: The cooperative control unit receives a first control instruction; The cooperative control unit obtains the second control instruction of each control unit according to the first control instruction; The cooperative control unit sends the second control instruction to each of the control units.

18. The vehicle control method according to claim 17, characterized in that: The cooperative control unit obtains the second control instruction of each control unit according to the first control instruction, including: Obtaining a state change target of the vehicle according to the first control instruction; According to the state change target, a corresponding second control instruction is sent to each of the control units.

19. The vehicle control method according to claim 18, characterized in that: The sending a corresponding second control instruction to each of the control units according to the state change target includes: Get vehicle status data; adjusting the state change target according to the vehicle state data to obtain an adjusted state change target; According to the adjusted state change target, a corresponding second control instruction is sent to each control unit.

20. The vehicle control method according to claim 18 or 19, characterized in that: The sending a corresponding second control instruction to each of the control units according to the state change target includes: Acquire the usage status of each control unit and the usage status of the execution unit corresponding to each control unit; According to the state change target, the usage state of each control unit and the usage state of the execution unit corresponding to each control unit, a corresponding second control instruction is sent to each control unit.

21. A controller, characterized in that: Used to execute the vehicle control method described in any one of claims 13-16.

22. A controller, characterized in that: Used to execute the vehicle control method described in any one of claims 17-20.

23. A vehicle, characterized in that: The vehicle heterogeneous redundancy device includes the vehicle heterogeneous redundancy device according to any one of claims 1 to 12.

24. A vehicle, characterized in that: Includes one or more of the controller according to claim 21 and the controller according to claim 22.